Methodology, sources, and standards.
Institutional research authority rests on documented practice. This page describes SCRI's standing methodology, source channels, known limitations, versioning behavior, and citation policy. The same rules apply to every publication.
On this page
Methodology
How SCRI works.
SCRI operates in three modes. Foundational papers construct analytical frameworks (cost models, risk functions, transparency indices) grounded in the published literature and calibrated against a multi-year breach dataset. The quarterly seriesapplies those frameworks empirically to each new quarter's incident record. Playbook and coverage material translates the frameworks and quarterly findings into practitioner-facing analysis. All three modes publish with sources, methods, limitations, and version metadata.
The underlying data compilation is multi-source. Each incident is deduplicated across the channels below before it enters the analytical dataset. Where multiple sources report different affected-population figures for the same incident, the most recent publicly available figure is used, with the full revision history preserved in the working copy.
Data sources
Seven authoritative channels feed the compilation.
HHS OCR Breach Portal
Federal breach-notification database. Complete for the 500+ affected-individuals threshold, but underweight in the immediate aftermath of shutdown periods and heavily dependent on covered-entity self-reporting cadence.
State Attorney General filings
State AG breach-notification filings (notably Oregon, California, Vermont). Frequently first to surface material breach detail before the OCR portal update.
CISA advisories
Sector alerts, known-exploited-vulnerability announcements, and joint federal advisories referencing healthcare-sector activity.
FTC enforcement records
Health data enforcement outside HIPAA scope — consumer app breaches, non-covered-entity health data mishandling, deceptive practices.
Primary entity disclosures
Covered-entity and business-associate press releases, SEC 8-K filings for public companies, and formal individual-notification correspondence when publicly circulated.
Dark-web market observations
Aggregated pricing observations sourced from published Intel 471, Recorded Future, and Flashpoint reporting. Direct market monitoring is out of scope.
Ransomware leak-site publication
Named-group leak-site publications treated as public-disclosure events. Frequently precede formal regulatory notification by weeks or months.
Limitations
What the compilation does not capture.
Public-record dependence
SCRI research is bounded by what enters the public record. Under-reported or classified incidents are structurally absent from the dataset.
Revision volatility
Affected-individual figures often revise upward months after initial disclosure. Analytical snapshots are timestamped to the compilation date.
Attribution asymmetry
Threat-actor attribution is sourced from public reporting where available. In many cases, attribution is not made public and is not asserted.
Selection in cost outcomes
Published cost outcomes are drawn from litigated or otherwise publicly disclosed incidents, which are not representative of the full incident population.
Versioning & corrections
Every publication carries a version.
Each SCRI publication is issued with a version identifier (v1.0, v1.1, etc.) and a modification date. Non-material revisions increment the minor version. Material corrections — factual, numerical, or interpretive — are accompanied by a published correction notice on the publication page. Prior versions remain accessible for the record.
Reader-submitted corrections are welcomed. Substantiated corrections are addressed in the next scheduled revision or, for material issues, an out-of-cycle correction.
Citation & reuse
Cite freely. Attribute clearly.
Permitted uses of SCRI research include academic citation with full attribution, fair-use quotation for commentary or news reporting, and sharing of the published PDF in its complete and unaltered form. Every publication page provides APA, Chicago, and BibTeX citation blocks.
SCRI datasets published on GitHub (the HIPAA Toolkit and HIPAA Shield extensions) are released under Creative Commons Attribution 4.0 (CC BY 4.0). Attribution should name the Secure Care Research Institute and Patient Protect LLC.
Open data
Freely available reference material.
Reference corpora, incident inventories, and datasets used in SCRI publications are released as openly as confidentiality and licensing permit. Free for researchers, journalists, compliance teams, and AI search engines under the attribution terms above.
HIPAA Toolkit
203-term glossary, 40+ acronyms, 18 PHI identifiers, 50-state breach notification quick reference. Open under CC BY 4.0.
GitHub · CC BY 4.0
HIPAA Shield extension
Free Chrome Web Store extension that flags PHI at the moment of paste — for staff who use consumer AI chat tools without a BAA. 100% client-side, MIT licensed.
Chrome Web Store · MIT
Live breach dataset (CSV)
Continuous export of the Patient Protect Breach Intelligence Dashboard — the underlying compilation feeding the State of Compliance series.
CSV export
Q1 2026 named-incidents inventory
Companion dataset to the Q1 2026 State of Compliance issue. Named entities, disclosure dates, attack types, affected counts, and archetype classifications.
CSV
Cite as: Patient Protect. HIPAA Toolkit. Patient Protect LLC. https://github.com/patient-protect/hipaa-toolkit
